Wij helpen bedrijven al 17 jaar
betere software te kiezen
Qualys Cloud Platform
Wat is Qualys Cloud Platform?
Beveiligingsrisico- en compliance management - Op tijd, binnen budget, op aanvraag - Qualys is levert een on-demand oplossing voor beveiligingsrisico- en compliance management. Qualys bewaakt het vulnerability management-proces van je bedrijf, volgt herstelmaatregelen en zorgt voor beleidsnaleving. QualysGuard is een breed geïmplementeerd on-demand platform voor beveiliging dat meer dan 150 miljoen IP-audits per jaar uitvoert - zonder software om te installeren en te onderhouden.
Wie gebruikt Qualys Cloud Platform?
Niet door leverancier verstrekt.
Twijfels over Qualys Cloud Platform?
Vergelijk met een populair alternatief
Qualys Cloud Platform
Reviews over Qualys Cloud Platform
Qualys Cloud Platform - A Complete Solution for all your security needs
Opmerkingen: Qualys helps companies discover, design, diagonoze,defend and monitor their business assets and corresponding threats .
Pluspunten:
The Console . The Qualys console has all the modules like VMDR , PC, SCA, PM , FIM etc. The Same agent can be used to perform all these tasks and scan for vulnerabilities . Its pretty straightforward and easy.
Minpunten:
Reporting format is a bit shaggy if you would ask me ..But having said that , the addition and deletion of controls also has to be more easily doable.
Eerder overwogen alternatieven:
In my oppinion, the best vulnerability management solution in the market
Pluspunten:
From my years of experience with vulnerability management solutions, Qualys is the best one in the market. First, it is really easy to set up, specially the cloud solution. In less than few hours you can start scanning your environment. Second, it's vulnerability database is constantly updated with the latest vulnerabilities. Third, it contains tons of apps that extends its capabilities (e.g. Asset management app, web application scanning, PCI compliance monitoring, etc.) ...
Minpunten:
The price tag is not the cheapest one. Their licensing model is per IP on the scope, not per live IPs. So for example, if you have three /24 networks with one server each, you will be paying to scan 765 IPs (255*3) instead of only 3 IPs.
Qualys is the No1 Vulnerability Scanner
Opmerkingen: very pleased, user friendly, quick and easy to get started but the product just gets better and better
Pluspunten:
this product really does allow you to see how secure your assets are. It also has a patch management feature. Great training videos and community
Minpunten:
sometimes the new features can cause confusion. This is normally due to consolidation
Lots of promises, great marketing. Real quality rather low. Decided to find something better.
Opmerkingen: That was my first contact with vulnerability management. Perhaps it's a good software for start or for small companies. I was able to recognize my needs and it helped a lot to find a professional solution.
Pluspunten:
Lots of features, agent available, flexible pricing. Software as a service, so you don't need any infrastructure.
Minpunten:
Useless unprofessional support, unable to solve any of my issues. They were closing unresolved issues. Lot of false positives. Support couldn't solve them, I got promises that it will be fixed in next release. Awful and unreliable reporting (errors on dashboards etc.). Very expensive. They're not using real cloud but couple of concentrators in different regions. Not useful for global customers. They promise they don't have access to customer data, but they request that to solve problems.
Qualys VM Review
Opmerkingen: It is one of the better solutions I have worked with. There are false-positives however this is common to most vulnerability scanners. This is one of the top 3 vulnerability scanners I would recommend. Take the time to understand what you require from the product and start building your tasks and reporting around it. The product will proof extremely valuable.
Pluspunten:
The interface is nice and clean. Free online training with labs aids in understanding the product. Easy deployment of agents on both Windows and Linux endpoints.
Minpunten:
Configuring scans was not the easiest of tasks to perform initially. I recommend doing the free online training first before embarking with the deployment. Reporting needs to be improved especially the look and feel of the .PDF reports. Scheduling tasks I found limited as I wanted a particular scan to run 2 days out of the month and was unable to do so. Instead I had to create 2 tasks. Could not find an option to create custom usernames.
Qualys the best vulnerability scanner
Opmerkingen: Based on the experience I have with Qualys, it is very impressive to capture the vulnerabilities, this compiles a complete report of the risks that your infrastructure has, in addition the patches have very precise information that allows you to carry out the remediation very effectively. The analyzes are detailed and very complete, it works very well to carry out the compliance stages of PCI, CIS, etc... Providing a great guarantee that periodically your organization has an armored infrastructure.
Pluspunten:
In the firts instance we could see its operation inside a beast and we were amazed, its different configurations to make scans allows to obtain much more complete results than other programs. Qualys as a pentesting tool allows you to analyze those areas of greatest risk within your organization to remedy them. The ability to perform scans for a particular plugin is one of the features that other software should envy to Qualys. Your reports have a very detailed information that allows you to quickly identify vulnerabilities.
Minpunten:
I have no negative comments, it has worked very well in the company and with our allies.
Best vulnerabilities management tool
Pluspunten:
Qualys is easily the best VM tool available because of many features like easy deployment, good UI, great customer support and outstanding VM features especially scanning, asset management, reporting etc. Container security and policy compliance modules work like a charm.
Minpunten:
There is no offline deployment in qualys, so for air gapped environments Qualys cannot be used.
Vulnerability scanning
Opmerkingen: Overall it has been very positive and we will continue to use it. It has helped us greatly lock down our environment.
Pluspunten:
Qualys gives high-quality reports in an easy to read format. The agent has been easy to install and has not caused any issues.
Minpunten:
We have had some instances where scan attempts ended up causing confusion or application outages when they were not designed to handle the scans.
Qualys VM
Opmerkingen: They need to make the product better .. Focus ion ease of use. Get a focus group going.
Pluspunten:
Agent deployment is simple. The software offers much if configured right. I dislike the add on services model.
Minpunten:
False positives. If a later software update rectifies an older vulnerability then there is no need to show asset is vulnerable. Vuln that shows up in Asset View is different in Vuln View.. Why? Salesperson quit after the sale which sucked. Replacement helped but was not focused on us.
Nice Tool for Security Scanning
Opmerkingen: We used Qualys for performing security scans on all Windows and Linux based servers being prepped for deployment so we had no vulnerabilities on servers being brought onto the production networks. Nice piece of mind and accountability for us as a deployment group.
Pluspunten:
convenient web based scanning utility for our enterprise
Minpunten:
frequently had password issues trying to use a group account
Eerder overwogen alternatieven:
A great Cyber Security Tool
Pluspunten:
I love the ease of use especially when you're managing multiple sites. The Qualys dashboard has to be the best hands down
Minpunten:
It gets a bit complicated when it comes to the set up and deployment. And another thing was the delay in endpoint scanning, it takes a while for the update information from the endpoints
The Best VM Solution
Opmerkingen: Extremely satisfied
Pluspunten:
Full fledged VAGreat suiteFlexible deployment optionsFree updates
Minpunten:
Integration between modulesWeak patch management integration
Patching , VAPT , Reporting All-In-One place
Opmerkingen: Its now supper impressive to showcase security matrix reports to management.
Pluspunten:
This product has high quality vulnerability scanner , supper easy to setup and implement in enterprise environment. Saves endpoint from any ransomeware , hack and vulnerabilities by patching them at the right time . Vast database of vulnerability detection and fixing .Reporting & dashboard are of highly professional quality. Its now supper impressive to showcase these reports to management.
Minpunten:
Nothing specific found till date.
Very outdated user interface
Pluspunten:
The platform provides pretty up to date scanning capabilities. Reporting contains direct links to available exploits.
Minpunten:
Very out dated user interface. Reporting modules have to be purchase separately along with actual scanners
Nice tool for Vulnerability Management.
Opmerkingen: Overall We are happy, Web interface is very interactive and training are awesome.
Pluspunten:
Easy to implement, enabling sensors are not much techie.
Minpunten:
Sometime handling false positive detection are really a tough task.
Comprehensive Solution for CloudSec Needs
Opmerkingen: Overall, Qualys Cloud Security is a comprehensive and powerful security tool
Pluspunten:
Comprehensive security coverage, scalability, and ease of use
Minpunten:
Cost can be subjective depending upon the org size. Also configurations are to be done very accurately for getting desired results.
Great cloud based vulnerability scanning tool.
Opmerkingen: Great vulnerability scanner to provide accurate vulnerability findings.
Pluspunten:
Qualysguard performs scan based on IP addresses rather than URL’s. It easily accessible from anywhere as its as cloud based scanner. Qualysguard supports scheduling of the scan for target system based on particular time and date and it also acknowledges and share the mail once the scan is completed. It can also perform the scan and give vulnerabilities as per compliance standards such as PCI DSS.
Minpunten:
Qualysguard doesn’t support scan for URL’s as we only need to provide IP address of the URL to perform the scan. This tool might be costly for small scale organizations.
A competent product
Pluspunten:
The Qualys product has been on the market for a long time. It's used by many people and you know you can trust it.
Minpunten:
The new and the old UI are run in parallel, and sometimes, you're swapped between them. This can be a bit confusing.
Good Easy to use
Opmerkingen: Really happy to use
Pluspunten:
True Positive Report for Vulnerability and VMDR is amazing really happy to use
Minpunten:
Sometime it take like 24 hours for agent to get reflect in the portal
Best paid tool for doing Vulnerability Scans
Opmerkingen: Costly tool but it is worth the money
Pluspunten:
It can scan the systems based on various unique standards like PCI DSS which other scanners by competitors doesn't have . We can define various scanning profiles for doing vulnerability scans . It supports scan based on IP rather than URL. As it is a cloud based scanner it can be accessed from anywhere. I like the feature that it has option to schedule scans in future.
Minpunten:
It can't perform credentialed based scans for external or public facing IP’s Does Not support URL based vulnerability scans for application.
A great VM Solution
Opmerkingen: Once you have the software set up, it is wonderful to use. There are improvements that can be made but this is a great solution for the money. Happy with the product so far.
Pluspunten:
The solution is very detailed in what information it collects. The Cloud agent runs as a service on the endpoints and references back to the cloud periodically (the interval is customizable). The GUI is very nice and they are updating things constantly. It is easy to see our Security stance from the different modules.
Minpunten:
There is no MSI file to deploy the software via GPO! Also, for me, the assetview module shows a different number of assets than the VMDR asset tab. Why there is a difference, I don't know.
Incompetent badly supported rubbish.
Pluspunten:
Nothing - I hate it.
Minpunten:
Their ridiculous false positives - apparently it's a critical incompliance that certain options aren't set in the gdm config file /etc/gdm.conf. Fair enough - if gdm was installed. A simple check that the file exists first would eliminate this and (of our 80+ compliance errors) most others. Complaining about mount options on non-existent filesystems, or that /etc/gshadow didn't match a regex - or did, I'm not sure from the report. The file has mode 0000 (so no permissions set at all). The fix was to chown root:root /etc/gshadow* Trust these amateurs at your own risk. If they are as incompetent as this, what are they missing?
Qualys analyse de vulnérabilité
Pluspunten:
Facilité de création de rapport, scheduler des analyses, filtre très fins
Minpunten:
rien à signaler sur cette solution d'analyse de vulnérabilité
Useful Vulnerabilty Management option
Pluspunten:
Detailed explanations and possible resolutions for vulnerabilities that are detected by the Cloud Agents.
Minpunten:
I have used other solutions as well on the same machines and they seem to detect quite a few different vulnerabilities, it seems neither give a rather complete list, so it's a good idea to use multiple solutions from different vendors with a different focus to get a clear insight in the ones that are classified as higher risks.
Qualys VM review - Analyst perspective
Pluspunten:
The tool is feature-rich, and managing the software is easy. Scans are easy to initiate and it doesnt cause any hassle for first-timers
Minpunten:
UI is lacklustre. Overall the tool is a bit slower in accessing compared to its competition